15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
2026-07-08T07:24:07Z•7fb9fe048c7fe67c9616993d9974af2d299b3758d5e1c20e69d5d329614429cd
CISA-KEVactively-exploitedagentic-workflowsair-gapandroid-maasauthentication-bypasscloud-securitycontainer-escapeexfiltrationfirmware-backdoorgithubkvmlinux-kernelmalwarephishingprivilege-escalationransomwareremote-code-executionroot-escaperoutersupply-chain
What happened
A collection of active and high-impact cyber threats and disclosures: Nebula Security disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel vulnerability that enables any logged-in user to obtain root on unpatched mainstream distributions. Multiple other critical flaws and active exploitations were reported — including an Adobe ColdFusion RCE added to CISA KEV (CVE-2026-48282), a KVM guest-to-host escape dubbed Januscape (CVE-2026-53359), and active probes targeting a critical Gitea Docker issue (CVE-2026-20896). Vendor and device advisories include a Tenda firmware hidden admin‑byp
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 7fb9fe048c7fe67c9616993d9974af2d299b3758d5e1c20e69d5d329614429cd
- Enrichment time
- 2026-07-08T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.